Explanation
Why the waste happens and who it affects.
It is typically used for incident investigations, audits and one-off analyses. Billing starts when the restore begins and continues every day until the restored table is dismissed by deleting it.
Investigators often finish their analysis and move on without deleting the _RST table, so the restore keeps billing for days or weeks with no queries against it. Because restores are billed on a minimum of 2 TB, even a small restore that is left running costs as much per day as a 2 TB one. Azure Advisor flags workspaces with active restored tables through its Consider removing unused restored tables recommendation.
Billing model
The pricing dimensions that drive this cost.
Restore is billed on the volume restored and the time the restore stays active.
- Restore charge
- Billed per GB per day for each UTC day the restore is active, until the _RST table is deleted
- Minimum volume
- Each restore is billed for at least 2 TB, even if less data is restored
- Minimum duration
- Each restore is billed for at least 12 hours, with partial-day billing on the first and last days
- Queries
- Querying a restored table has no extra charge because restored tables use the Analytics plan
How to detect
4 checks to find it in your estate.
- Review the Azure Advisor cost recommendation Consider removing unused restored tables on microsoft.operationalinsights/workspaces resources
- List tables in each workspace (Tables view in the portal or the Tables - Get API without a table name) and find those whose name ends in _RST and that carry restoredLogs properties
- With query auditing enabled, search LAQueryLogs QueryText for each _RST table name; restores with no queries for several days are idle
- In Cost Management, filter to the Log Analytics workspace and look for data restore charges on days when no investigation is open
How to fix
4 ways to remove the waste.
- Delete the _RST table as soon as the investigation is finished; deleting a restored table stops restore billing and does not delete data in the source table
- Restore only the time range needed, keeping in mind the 2 TB and 12-hour billing minimums, and set an owner and end date for every restore
- Use search jobs when only records matching specific criteria are needed, and export jobs for one-time bulk extracts, instead of restoring whole time ranges
- Set up an Azure Advisor alert on the unused restored tables recommendation so leftover restores are caught automatically
Documentation
Vendor references for pricing and configuration.